Skip to content

ManageEngine vulnerabilities

1 CVE tracked

ManageEngine appears in recent reports within two key contexts: a supply chain attack targeting users and a critical authentication vulnerability. According to The DFIR Report, a user searching for ManageEngine OpManager was led to a fake site and downloaded a trojanized MSI installer, initiating an intrusion that deployed BumbleBee, AdaptixC2, and ultimately Akira ransomware. Concurrently, an authentication bypass vulnerability (CVE-2026-12571) was disclosed in ManageEngine DDI Central's password-reset workflow, allowing account takeover. Defenders must ensure software downloads originate only from official sources, hunt for indicators of AdaptixC2 and BumbleBee activity in the network, and urgently apply the patch for CVE-2026-12571.

Azərbaycanca: ManageEngine son hesabatlarda iki əsas kontekstdə görünür: istifadəçiləri hədəf alan təchizat zənciri hücumu və kritik autentifikasiya zəifliyi. DFIR Report təhlilinə əsasən, ManageEngine OpManager yükləmək istəyən istifadəçi saxta saytdan trojanlaşdırılmış MSI quraşdırıcı endirib və bu, BumbleBee, AdaptixC2 və Akira ransomware ilə nəticələnən genişmiqyaslı müdaxiləyə səbəb olub. Paralel olaraq, ManageEngine DDI Central məhsulunda parol sıfırlama mexanizmində autentifikasiyadan yayınma boşluğu (CVE-2026-12571) aşkarlanıb və bu, hesabın ələ keçirilməsinə imkan verir. Müdafiəçilər yazılım yükləmələrinin yalnız rəsmi mənbələrdən edildiyinə əmin olmalı, şəbəkədə AdaptixC2 və BumbleBee göstəricilərini axtarmalı və CVE-2026-12571 üçün təcili yamağı tətbiq etməlidir.

This vendor's CVEs1

This hub is built from skopnix's own reporting on ManageEngine: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.